← Vulnerability feed

Vulnerability record · CVE-2014-2375 · published 15 September 2014

CVE-2014-2375: Ecava integraxor permissions and access controls vulnerability

Ecava · Integraxor

Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive information or cause a denial of service (disk consumption), via the CSV export feature.

8.3 CVSS 2.0 High EPSS 2.3% · top 17.3% CWE-73 · CWE-73CWE-264 · Permissions and access controls
8.3CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive information or cause a denial of service (disk consumption), via the CSV export feature.

AV:N/AC:M/Au:N/C:P/I:P/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2375 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4597Ecava integraxor memory buffer overflow vulnerabilityStack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Interface (H…EPSS 19%9.8CVE-2017-6050Ecava integraxor sql injection vulnerabilityA SQL Injection issue was discovered in Ecava IntegraXor Versions 5.2.1231.0 and prior. The application fails to properly validate user input, which …EPSS 3.5%9.8CVE-2016-8341Ecava integraxor sql injection vulnerabilityAn issue was discovered in Ecava IntegraXor Version 5.0.413.0. The Ecava IntegraXor web server has parameters that are vulnerable to SQL injection. I…EPSS 1.7%9.3CVE-2012-4700Ecava integraxor memory buffer overflow vulnerabilityMultiple buffer overflows in an ActiveX control in PE3DO32A.ocx in IntegraXor SCADA Server 4.00 build 4250.0 and earlier allow remote attackers to ex…EPSS 3.8%9.3CVE-2012-0246Ecava integraxor path traversal vulnerabilityDirectory traversal vulnerability in an unspecified ActiveX control in Ecava IntegraXor before 3.71.4200 allows remote attackers to execute arbitrary…EPSS 5.9%7.8CVE-2014-0753Ecava integraxor stack-based buffer overflow vulnerabilityStack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system cras…EPSS 2.5%7.5CVE-2016-2306Ecava integraxor vulnerabilityThe HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the networ…EPSS 1.9%7.5CVE-2014-2376Ecava integraxor sql injection vulnerabilitySQL injection vulnerability in Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to exe…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2014-2375), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.